PT-2026-94307 · Npm · Vm2

·

CVE-2026-92935

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v4.0

9.5

Critical

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions vm2 versions 3.11.4 through 3.11.6
Description A sandbox escape exists when the NodeVM constructor incorrectly validates the require configuration. By providing an array-shaped value to the require parameter while nesting is enabled, the hasRealRequireConfig check is bypassed. This allows the makeResolverFromLegacyOptions() function to return a resolver that grants access to the host vm2 module. An attacker can then instantiate an inner NodeVM with a custom builtin allowlist, such as child process, to execute arbitrary commands with the privileges of the host Node.js process, bypassing outer builtin restrictions.
Recommendations Update to version 3.11.7.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92935
GHSA-8HR7-R645-PC6W

Affected Products

Vm2